---
title: "Who is liable for business email compromise losses?"
description: "General information on who bears a business email compromise loss: the payer, the vendor, the bank or an insurer, and the factors that usually decide it. Not legal advice."
url: https://realpayee.com/answers/who-is-liable-for-business-email-compromise-losses
canonical: https://realpayee.com/answers/who-is-liable-for-business-email-compromise-losses
date_published: 2026-10-05
date_modified: 2026-10-05
author: RealPayee
---

# Who is liable for business email compromise losses?

> There is no single rule. In many BEC cases the business that sent the payment bears the loss first, because it authorized the transfer. Whether it can recover from the vendor, a bank or an insurer usually depends on contract terms, the payment law that applies, insurance wording and the facts, including which side had reasonable controls and missed warning signs.

Because recovery is uncertain and slow, the practical answer is prevention: verify bank-detail changes and large payment requests before money moves, and keep evidence that you did.

_Published 2026-10-05 · Updated 2026-10-05 · By RealPayee_

> [!NOTE]
> This page is general information, not legal advice. Liability depends on your contracts, the law that applies and the facts. Talk to a qualified lawyer about a specific loss.

## Who might bear the loss

- **The payer.** It sent the money, often to an account it was told to use. Banks generally execute authorized payment instructions.
- **The vendor.** If the vendor's own mailbox was compromised, the payer may argue the vendor should bear some or all of the loss. Contracts sometimes address this; often they do not.
- **The banks.** Banks may be involved if they did not follow agreed security procedures, but authorized payments are hard to dispute.
- **An insurer.** Social engineering or funds transfer fraud coverage may respond, subject to sub-limits and conditions. See [cyber insurance and social engineering fraud](https://realpayee.com/answers/do-cyber-insurance-policies-cover-social-engineering-fraud).

## Factors that often matter

- What your contracts with the vendor and your bank say about payment instructions and security procedures.
- Whether a written verification procedure existed and was followed.
- Who was compromised (your mailbox, the vendor's, or neither) and who could most easily have spotted the fraud.
- How quickly the fraud was reported. Fast reporting to your bank and to the FBI's IC3 improves the chance of recovering funds.

## What to do now

- Add a clause to vendor contracts that bank-detail changes are only valid after out-of-band confirmation.
- Adopt a written [bank-change policy](https://realpayee.com/templates/vendor-bank-change-policy) and keep records showing it is followed.
- Check your insurance for social engineering coverage and its verification conditions.

## Frequently asked questions

### Can the bank reverse a wire sent to a fraudster?

Sometimes, if you act very fast and the funds have not moved on. Call your bank's fraud line immediately and report to IC3. Recovery is never guaranteed.

### How big are BEC losses?

The FBI's IC3 recorded about $3.0 billion in reported BEC losses in 2025 across 24,768 complaints. See [payment fraud statistics](https://realpayee.com/payment-fraud-statistics).

## Sources

- [McDonald Hopkins: The sobering truth of the FBI's 2025 IC3 report](https://www.mcdonaldhopkins.com/insights/news/the-sobering-truth-of-the-fbis-2025-internet-crime-complaint-center-report)

## Related

- [Do cyber insurance policies cover social engineering fraud?](https://realpayee.com/answers/do-cyber-insurance-policies-cover-social-engineering-fraud) - General information on whether cyber or crime insurance covers social engineering fraud such as fake vendor bank changes, and what insurers commonly ask for. Not insurance advice. (markdown: https://realpayee.com/answers/do-cyber-insurance-policies-cover-social-engineering-fraud.md)
- [Wire fraud prevention: how to stop bank wire fraud](https://realpayee.com/wire-fraud-prevention) - Controls that prevent business wire fraud: out-of-band verification, payment thresholds, dual approval and audit trails. (markdown: https://realpayee.com/wire-fraud-prevention.md)
- [Business email compromise examples and how to stop them](https://realpayee.com/blog/business-email-compromise-examples) - Seven business email compromise (BEC) examples finance teams see, the red flags in each, and the specific control that stops it before money moves. (markdown: https://realpayee.com/blog/business-email-compromise-examples.md)
- [Free vendor bank-change verification policy template](https://realpayee.com/templates/vendor-bank-change-policy) - A free, copy-ready vendor bank-detail change and callback verification policy template plus checklist for AP teams. (markdown: https://realpayee.com/templates/vendor-bank-change-policy.md)

---

Canonical HTML: https://realpayee.com/answers/who-is-liable-for-business-email-compromise-losses · Site index: https://realpayee.com/llms.txt · Book a demo: https://realpayee.com/demo
